Services is stopping with user N/A
- From: jering <jering@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Wed, 31 Jan 2007 09:31:00 -0800
Server: Windows Server 2003 SP1 R2
Domain mode: 2003
The server this issue resides on is the only domain controller in the domain.
Suddenly, severeal major services is entering the stopped state. Example:
Event Type: Information
Event Source: Service Control Manager
Event Category: None
Event ID: 7036
Date: 22.12.2006
Time: 07:09:42
User: N/A
Computer: DC01
Description:
The Windows Management Instrumentation service entered the stopped state.
Some of the services this is happening to:
Network Connections service, Kerberos Key Distribution Center service, DNS
Server service, Logical Disk Manager service, The Cryptographic Services
service, The Terminal Server Licensing service.
And a lot more...so the server have to be restarted. This happens 3-4 times
a day.
After it happens a lot of events is recorded, like:
Event Type: Error
Event Source: NETLOGON
Event Category: None
Event ID: 5723
Date: 22.12.2006
Time: 01:38:35
User: N/A
Computer: DC01
Description:
The session setup from computer '047797420361' failed because the security
database does not contain a trust account '047797420361$' referenced by the
specified computer.
USER ACTION
If this is the first occurrence of this event for the specified computer and
account, this may be a transient issue that doesn't require any action at
this time. Otherwise, the following steps may be taken to resolve this
problem:
If '047797420361$' is a legitimate machine account for the computer
'047797420361', then '047797420361' should be rejoined to the domain.
If '047797420361$' is a legitimate interdomain trust account, then the trust
should be recreated.
Otherwise, assuming that '047797420361$' is not a legitimate account, the
following action should be taken on '047797420361':
If '047797420361' is a Domain Controller, then the trust associated with
'047797420361$' should be deleted.
If '047797420361' is not a Domain Controller, it should be disjoined from
the domain.
Data:
0000: 8b 01 00 c0 ..À
Event Type: Error
Event Source: Kerberos
Event Category: None
Event ID: 7
Date: 31.01.2007
Time: 06:06:42
User: N/A
Computer: DC01
Description:
The kerberos subsystem encountered a PAC verification failure. This
indicates that the PAC from the client DC01$ in realm DOMAIN.LOCAL had a PAC
which failed to verify or was modified. Contact your system administrator.
Data:
0000: 61 00 00 c0 a..À
When the server is restarted, the same happens after some hours.
What could this caused by?
The server is running Norman AV, and I`ve also did a search with Trend
Housecall, but no viruses or malicious items were found...
.
- Prev by Date: Re: TCP/IP Properties Windows Server 2003
- Next by Date: Re: Local GPO vs Domain/AD GPO
- Previous by thread: Can not see Windows Server 2003 in network places
- Next by thread: Access Denied After Re-Joining the Computer to the Domain
- Index(es):
Relevant Pages
|